Threats Tagged 'ghsa-xwmw-prc4-v3cr'
View all threats tagged with 'ghsa-xwmw-prc4-v3cr'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-xwmw-prc4-v3cr'
Click on any threat for detailed analysis and mitigation recommendations
Obot versions up to 0.22.1 with authentication enabled are vulnerable to an OAuth dynamic client registration flaw that allows an attacker to steal API tokens via audience confusion. An unauthenticated attacker can register an OAuth client with an arbitrary redirect URI, and the authorization flow auto-completes without user consent. If a logged-in user visits a crafted authorization URL, the attacker receives an authorization code that can be exchanged for an access token carrying the victim's full group permissions. This token can be used against API endpoints the victim is authorized for, enabling unauthorized access until token revocation. The vulnerability is fixed in version 0.23.0 with added consent screens, token audience restrictions, and validation. Join the discussion | GCVE Database | 09/18/2026, 17:59:35 UTC Added: 09/19/2026, 01:28:16 UTC |
Showing 1 to 1 of 1 result